modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
http://lists.opensuse.org/opensuse-bugs/2015-06/msg02580.html | mailing list |
http://lists.opensuse.org/opensuse-updates/2015-11/msg00098.html | vendor advisory |
http://lists.opensuse.org/opensuse-bugs/2015-06/msg02585.html | mailing list |